Legal
Privacy Policy
Last updated: July 11, 2026
Overview
Notedog is a private journal app. By default, your journal content — the text, images, and files in your entries — is stored only on your device, and the app works without an internet connection. We do not collect your journal content or persist it on servers we operate. Content leaves your device only when you enable a feature that requires it, such as Git sync, browser access, the optional internet tunnel, or a connected AI assistant, as described below.
Data Storage
All journal entries, images, and settings are stored in the app's private storage on your device. Our servers do not persist journal content. If you enable the optional internet tunnel, our relay forwards requests and responses in memory and stores only the limited account information described under “Tunnel account & sign-in.”
Network Access
Notedog only uses network access in optional, user-initiated scenarios:
- Git sync — If you configure a remote Git repository, the app connects to that server to push and pull your journal data. Credentials you provide are stored in encrypted storage on your device.
- LAN web server — If you start the built-in web server, the app serves your journal over your local network so you can edit from a browser on another device. This server is only active while you keep it running and is not accessible from the internet.
- Internet tunnel — If you opt in to the tunnel feature, the app opens an outbound WebSocket to a relay we operate at
t.notedog.runso paired browsers outside your LAN can reach the same web server. Traffic is encrypted in transit on each connection to the relay. The relay forwards requests and responses in memory; it does not persist any of the journal data, request bodies, or response bodies that pass through it. The tunnel is only active while you keep it running. Because the relay sits between your device and the public internet, you should treat the tunnel as use-at-your-own-risk and only enable it when you understand that consequence. - Direct local connection — When the tunnel is on and a paired browser is on the same local network as your phone, the app can send data straight to your phone over that network for speed, while still using the tunnel's web address. It is opportunistic: it falls back to the tunnel whenever the direct path isn't reachable, and you can turn it off in the app's settings. So a browser can trust the direct connection in the background, your device obtains a standard TLS certificate from Let's Encrypt for a name unique to your device. Two things follow from that: (1) the name embeds a random, per-install identifier for your device — not your name, account, email, location, or any hardware ID — and, like every publicly-trusted certificate, it is recorded in public Certificate Transparency logs; and (2) our relay stores that random identifier with your account so it can answer the DNS lookups the certificate needs (those lookups also carry your device's private local address, such as
192.168.x.x). The certificate's private key is generated on your device and never leaves it, and a new identifier is generated if you reinstall.
Tunnel account & sign-in
The internet tunnel is optional. If you enable it, some information beyond your device is involved:
- Google Sign-In — you sign in with Google so the relay can tie your tunnel to you. We receive your Google account identifier and email address.
- Relay account — our relay at
t.notedog.run(hosted on Fly.io in the United States) stores a small account record: your account identifier, your chosen subdomain, session and refresh tokens, your subscription status, and — if you use the direct local connection — the random per-device identifier described under “Network Access.” Because the relay is hosted in the US, this account data is transferred to and processed there. The relay does not store your journal content, entry images, or the request/response bodies that pass through the tunnel. - Subscription — the tunnel is a subscription billed through Google Play; Google processes the payment and shares your subscription status with us.
- Connected AI assistants — if you link a third-party AI assistant (for example Claude or ChatGPT) to your journal over the tunnel, you authorize it to read and write entries through that connection. That access happens at your direction and under the assistant's own terms.
Analytics & Tracking
Notedog contains no analytics, advertising, or tracking libraries. No usage data is collected.
Third-Party Services
The core app integrates with no third-party services. External connections happen only through features you configure or enable: Git remotes you set up; and, if you turn on the tunnel, Google Sign-In, Google Play billing, our relay, and any AI assistant you choose to connect (all described under “Tunnel account & sign-in”).
Permissions
- Internet & network state — Required for Git sync, the LAN web server, and the tunnel.
- Foreground service — Runs the web server in the foreground (with the notification below) while it is on.
- Notifications — Used to show a notification while the web server is running.
- Ignore battery optimizations — Optional. If you allow it, the app can keep the server and tunnel connection alive while the screen is off, so remote access stays reachable; you can decline or revoke it at any time.
- Camera — Used only when you choose to attach a photo to a journal entry.
Deleting your tunnel account
Notedog's local copy of your journal is stored on your device, so uninstalling the app removes that local copy. Uninstalling does not delete copies you sent to a Git remote, exported, or shared with a third party. In the app you can remove your custom subdomain at any time from the tunnel settings. To delete your entire relay account — your stored Google identifier and email, session tokens, subdomain, subscription record, and any direct-local-connection device identifier — email us at hiya@hibariya.org and we will erase it.
Changes to This Policy
If we update this policy, the new version will be included in the next app update. Continued use of the app constitutes acceptance of the updated policy.
Contact
If you have questions about this policy, contact us at hiya@hibariya.org.